CVE-2015-7190

Publication date 5 November 2015

Last updated 24 July 2024


Ubuntu priority

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 15.10 wily
Not affected
15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected

Notes


chrisccoulson

Android only